TajMahal is a highly sophisticated espionage-oriented spyware framework and threat activity cluster known for long-term covert collection from compromised systems. It has been described as an advanced persistent threat framework with roughly 80 modules and a broad surveillance feature set, including backdoors, loaders, orchestrators, command-and-control communications components, audio recording, keylogging, screen and webcam capture, document theft, cryptographic key theft, and local file indexing. The platform supports automated collection, staging, compression, and exfiltration of victim data, including the ability to index files into a send queue and steal documents from local systems, including print spooler queue contents. Reported activity indicates it was active for at least five years and targeted at least one diplomatic entity in Central Asia. The breadth of collection and surveillance functionality, combined with its modular architecture and sustained covert operation, is consistent with a high-end cyber-espionage capability.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TajMahal is a highly sophisticated APT spyware framework active for at least five years, featuring up to 80 malicious modules for espionage, including data theft, surveillance, and credential stealing. It has targeted at least one diplomatic entity in Central Asia.
Steals documents from local systems, including from the print spooler queue.
Indexes and compresses files into an exfiltration queue.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.